Only the current main branch and production deployment at www.bergaman.dev are supported. The v1-legacy release is archived and does not receive security updates.
Use GitHub's private vulnerability reporting feature for this repository, or email contact@bergaman.dev with a concise description, affected route and reproduction steps.
Do not open a public issue containing credentials, personal data, database content or working exploit details.
If a credential is committed or exposed:
- Revoke or rotate it at the provider immediately.
- Update every deployment environment that consumes it.
- Redeploy and verify the old credential no longer works.
- Resolve the GitHub secret-scanning alert as revoked.
- Review provider access logs and repository history for misuse.
Deleting a branch, tag or commit reference does not revoke a leaked credential.